TOTP Authenticator does not collect, transmit, sell or share user data.
Data storage
Account information, including issuer names, account names and TOTP secrets, is stored exclusively in Chrome's local extension storage on the user's device. Vault data is encrypted at rest with AES-GCM using a key derived from the master password chosen by the user.
The extension has no server, cloud account, analytics system, advertising SDK or third-party data integration.
Authentication information
TOTP secrets and generated verification codes are used only to provide the extension's single purpose: generating time-based one-time passwords on the user's device. They are never transmitted to the developer or another service.
Camera
Camera access is requested only after the user selects Scan with camera. Video frames are processed locally to recognize a QR code. They are not recorded, retained or transmitted.
QR image files
When the user chooses a QR image, that file is read locally for QR-code recognition. The image is not uploaded, stored or shared.
Clipboard
Clipboard access is used only when the user explicitly requests that a generated verification code be copied by clicking it, activating it with the keyboard or pressing Ctrl + C while an account row is focused. The extension does not read clipboard contents.
Backups
Backup files are created only when requested by the user. They contain encrypted vault data and are saved to a location selected through the browser. Importing a backup reads the selected file locally and replaces the existing local vault after confirmation.
Data sharing and sale
No user data is sold, shared with third parties, used for advertising, used for creditworthiness or transferred for purposes unrelated to the extension's single purpose.
Data deletion
Users can remove individual accounts inside the extension. Uninstalling the extension removes its local Chrome storage according to Chrome's normal extension-storage behavior. The developer retains no server-side copy because no data is sent to a server.
Children's privacy
The extension is a general-purpose authentication utility and is not directed to children. It does not knowingly collect personal information from anyone, including children.
Changes to this policy
If the extension's data practices change, this policy will be updated before the changed version is distributed. The date at the top identifies the latest revision.
Contact
Questions about this policy can be directed to the developer through the developer's GitHub profile.
Google Authenticator and Google Chrome are trademarks of Google LLC. TOTP Authenticator is independent software and is not affiliated with or endorsed by Google.